What's in this template?
This My Health Record Data Breach Notification Procedure gives Australian healthcare practices the operational steps for section 75 of the My Health Records Act 2012: the mandatory duty to notify both the System Operator (the Australian Digital Health Agency) and the OAIC of a notifiable data breach involving the My Health Record system, as soon as practicable. It is built from the OAIC's Guide to Mandatory Data Breach Notification in the My Health Record System.
The template includes:
- The relationship to your general Data Breach Response Plan, stated as a direct comparison table so staff never mistake one duty for the other
- The three notifiable data breach categories under section 75, with a healthcare example for each
- An immediate containment checklist
- A 5-step dual notification procedure, with owners and timeframes
- The notification content checklist, including the explicit rule against naming affected patients to the OAIC
- Appendix A: a breach register for every incident assessed, whether or not it met the notification threshold
Editable placeholder fields
{{practice_name}},{{hpi_o}}{{responsible_officer}},{{responsible_officer_email}}{{privacy_officer}},{{it_support_contact}}{{effective_date}},{{next_review_date}},{{approved_by}}
This is not your general data breach plan
This is the single most important thing to understand about this document: section 75 is a separate legal duty from the Notifiable Data Breaches scheme, and having a Data Breach Response Plan does not discharge it.
| This procedure (My Health Records Act, s75) | Data Breach Response Plan (Privacy Act, NDB scheme) | |
|---|---|---|
| Applies to | Any registered My Health Record provider organisation, for incidents involving the My Health Record system | Any APP entity, for an eligible data breach of personal information generally |
| Threshold | A breach or possible breach. No serious harm test | An eligible data breach: likely to result in serious harm |
| Who is notified | The System Operator AND the OAIC | Affected individuals AND the OAIC |
| Timeframe | As soon as practicable | As soon as practicable, generally within 30 days of an assessment |
The threshold here is deliberately lower than the general scheme. A possible breach is enough to trigger notification, and there is no serious harm test to clear first. That is why a practice needs this procedure as a fast, separate trigger rather than folding My Health Record incidents into the general plan and hoping the same steps cover both.
In practice, many incidents trigger both procedures at once. A staff member inappropriately viewing a patient's My Health Record, for example, is assessed under this procedure first because the notification duty is faster, and the Privacy Officer separately runs the general NDB assessment in parallel. Both notifications go out. Neither replaces the other.
What the law actually requires
Section 75 defines a notifiable data breach across three categories, and any one of them is enough on its own:
- Unauthorised collection, use or disclosure: a person has, or may have, contravened the Act in a way involving unauthorised collection, use or disclosure of health information in a My Health Record.
- System compromise: an event has, or may have, occurred that compromises, or may compromise, the security or integrity of the My Health Record system.
- Circumstantial threat: circumstances have, or may have, arisen that compromise, or may compromise, the system's security or integrity.
Categories 2 and 3 do not require an actual contravention of the Act. A leaked password list containing the practice's My Health Record login, or a NASH PKI certificate found on an unattended device, can each be a notifiable event on its own, before anyone has actually misused anything.
Once identified, both the System Operator and the OAIC must be told as soon as practicable. The OAIC's guidance is explicit that reporting should not wait for containment to be finished or for every fact to be confirmed. An incomplete notification, followed up with more detail as it becomes available, is the expected pattern, not a failure to notify properly the first time.
How to customise this template
- Download the Word document and replace every
{{placeholder}}with your details. - Confirm your Responsible Officer, the person named to the Australian Digital Health Agency, matches the person named in your Security and Access Policy.
- Brief staff on Section 4, the three notifiable categories, so a possible breach is reported the day it is noticed rather than sat on while someone tries to confirm it.
- Confirm the relationship in Section 3 is understood by whoever leads your general breach response, so a My Health Record incident is never run through only one of the two procedures.
- Keep the notification content checklist in Section 7 handy, and note the rule against naming affected patients in the OAIC notification.
- Review every two years, or sooner after any incident handled under it.
Related templates and tools
- Data Breach Response Plan: the general NDB scheme plan. Run alongside this procedure, not instead of it, whenever a My Health Record incident may also be an eligible data breach.
- My Health Record Security and Access Policy: the Rule 42 policy this procedure supports.
- My Health Record Authorised User Access Register: identifies who had access, which is often the first question in a breach assessment.
- Notifiable Data Breach assessment tool: use it to work through the general NDB threshold in parallel.
- Healthcare privacy and cyber security: how the My Health Records Act sits inside the wider privacy picture.
Frequently asked questions
Do we still need a general Data Breach Response Plan if we have this procedure?
Yes. This procedure only covers the section 75 duty to notify the System Operator and the OAIC about a My Health Record incident. It does not cover notifying affected patients, which is a separate obligation under the general Notifiable Data Breaches scheme, and it does not cover a breach that has nothing to do with the My Health Record system. Most practices need both documents.
What counts as a "possible" breach under section 75?
Any of the three categories in the Act: a possible unauthorised collection, use or disclosure of health information in a My Health Record, a possible compromise of the system's security or integrity, or circumstances that may compromise it. The word "may" is doing real work here. You do not need to confirm the breach actually happened or that harm resulted before the notification duty applies.
Who do we notify: the System Operator, the OAIC, or both?
Both, for a registered healthcare provider organisation. The System Operator is the Australian Digital Health Agency. Some entity types, such as state and territory authorities, notify the System Operator only, but a general practice or allied health provider notifies both.
How fast does this have to happen?
As soon as practicable. The OAIC's guidance does not set a fixed number of days, but it is explicit that notification should not be delayed while containment efforts are still under way, and that an initial notification can be updated with more information later. Treat "as soon as practicable" as the same working session the incident is discovered in, not the next business day.
Can we name the affected patient in the notification to the OAIC?
No. The template's notification checklist carries this as an explicit rule: identify affected people internally by record or reference number, and do not include their identities in what is sent to the OAIC.
Is there a penalty for not reporting?
Yes, civil penalties apply to reporting entities that fail to comply with the section 75 duty. The System Operator itself faces no penalty for failing to pass a breach on to the OAIC, but the OAIC can investigate where it suspects a breach has gone unreported, which is a separate exposure for the practice if its own notification never happened.
Does every incident go in the breach register, or only the ones we report?
Every incident assessed under Section 4 of this procedure, whether or not it met the notification threshold. That record is what the System Operator or the OAIC will expect to see if they ask how the practice handles potential breaches, and it is also the evidence that near-misses are being tracked, not just confirmed incidents.